Description
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
Remediation
References
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO2RMVVZVV6NFTU46B5RYRK7ZCXYARZS/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M6BJG6RGDH7ZWVVAUFBFI5L32RSMQN2S/
https://snyk.io/vuln/npm:marked:20170112
Related Vulnerabilities
CVE-2023-31581 Vulnerability in maven package com.usthe.sureness:sureness-core
CVE-2021-23926 Vulnerability in maven package org.apache.xmlbeans:xmlbeans
CVE-2020-12668 Vulnerability in maven package com.hubspot.jinjava:jinjava
CVE-2020-26302 Vulnerability in maven package org.webjars.bowergithub.arasatasaygin:is.js
CVE-2023-47324 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web